Lines Matching refs:audit
24 * write binary audit records directly to a file.
43 #include <bsm/audit.h>
81 /* minimum reasonable size in bytes to roll over an audit file */
270 DPRINT((dbfp, "binfile: Loading audit list from audit service "
336 DPRINT((dbfp, "loadauditlist: close / open audit.log(4)\n"));
397 * write_file_token - put the file token into the audit log
619 * to ensure audit log does not grow above size limit
743 * exceeded or the current file system fills up, and "audit -s" with
744 * changed parameters. For "audit -n" a new log file is opened
747 * This function manages one or more audit directories as follows:
801 * audit log is unrestricted.
805 DPRINT((dbfp, "binfile: maxsize exceeded, opening new audit "
936 * corresponding to the audit(1M) flags -s and -n
938 * kvlist is NULL only if auditd caught a SIGUSR1 (audit -n), so after the first
959 reason = 1; /* audit -n */
961 reason = 2; /* audit -s */
988 case 2: /* audit -s */
1009 case 1: /* audit -n */